baillie.com
bd_07a6545562602e1c · schema v1 · pii pii-v1
Full breach record for baillie.com →Threat-actor claim — not a regulatory filing
This row is a claim by the ransomware group Cactus on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Source: Ransomware.live
Post text · scraped from the leak site
<p>Building Materials.<br><br>“The Baillie Group family of brands are providers of high-quality hardwood lumber! Together we are a family of hardwood lumber suppliers capable of providing customers access to a portfolio of hardwood products suitable for any application. ”<br><br>Website: <a href="https://www.baillie.com/">https://www.baillie.com/<\/a><br><br>Revenue : $130.5M<br><br>Address: 4002 Legion Dr, Hamburg, New York, 14075, United States<br><br>Phone Number: (716) 649-2850<br><br><mark class="marker-yellow"><strong>Download link #1:<\/strong><\/mark> <a href="https://6wuivqgrv2g7brcwhjw5co3vligiqowpumzkcyebku7i2busrvlxnzid.onion/BAILLIE/PROOF/">https://6wuivqgrv2g7brcwhjw5co3vligiqowpumzkcyebku7i2busrvlxnzid.onion/BAILLIE/PROOF/<\/a><br><br><mark class="marker-yellow"><strong>Mirror:<\/strong><\/mark> <a href="https://cactus5dqnqkppa5ayckiyk6dttpqwczdqphv5mxh4dkk5ct544q5aad.onion/BAILLIE/PROOF/">https://cactus5dqnqkppa5ayckiyk6dttpqwczdqphv5mxh4dkk5ct544q5aad.onion/BAILLIE/PROOF/<\/a><br><br><mark class="marker-yellow"><strong>DATA DESCRIPTIONS:<\/strong><\/mark> Personal identifiable information, сorporate confidential documents, financial data\payroll, legal docs, HR dept data, employees\executives personal documents, corporate correspondence, etc.<\/p><p><img src="/uploads/Passport_Meyer_Jill_acda6991d8.png" alt="Passport - Meyer Jill.png"><img src="/uploads/Stop_Loss_Disclosure_2_13_24_016574cdc9.png" alt="Stop Loss Disclosure 2.13.24.png"><img src="/uploads/Passport_Jeffrey_S_Meyer_Exp_02082026_fbad2a6d31.png" alt="Passport_Jeffrey S Meyer_Exp 02082026.png"><img src="/uploads/December_P_and_L_5be83db069.png" alt="December P&L.png"><img src="/uploads/Privileged_and_Confidential_Discussion_with_Legal_Counsel_f2497ceca9.png" alt="Privileged and Confidential Discussion with Legal Counsel.png"><\/p>
Source provenance
- Source URL
- https://cactusbloguuodvqjmnzlwetjlpj6aggc6iocwhuupb47laukux7ckid.onion/posts/BAILLIE
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 12, 2025
- Raw hash
- c61d0e1d88e96953241b176fff242ffb427c73bf71c5de357a9cc117557e32eb
Reporting entity
- Name
- cactus
Victim entity
- Name
- baillie.comnorm: bailliecom
- Domain
- baillie.com
- Industry
- Constructionllm
What this source establishes
- Source ceiling
- A leak-site claim can't tell us: discovery date · materiality · notification · affected count · confirmed data types · compliance clock. These stay blank until a regulatory filing or victim disclosure lands.
- Attack vector
- Ransomware· cactus
- Threat actor
- CactusExternalFinancial
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.